You should revoke the API key in Stripe, and don’t add a new one until you worked out where the leak is coming from. Screenshot your Stripe plugin(s)/API calls to Stripe, and someone here will be able to tell you (though cross out the key, even though revoked, to be safe)